Role Responsibility Matrix

Defined security responsibilities for every role in the organization.

CategoryCEO / ExecCISOAppSecDevOpsProject LeadDeveloperAuditor
Strategy & PolicyApproveAuthorImplementImplementAdoptAdoptReview
Risk ManagementAccept (high)Own registerAssessMitigateCommunicateReportReview
Vulnerability MgmtGovernTriageRemediate (infra)AllocateRemediate (code)Sample
Incident ResponseNotifyLeadInvestigateContainSupportSupportReview post-mortem
ComplianceSign-offOwn programEvidenceEvidenceCooperateCooperateAudit
TrainingChampionDefineDeliverCompleteEnforceCompleteVerify
Change MgmtGovernReviewImplementApproveExecuteSample